Skip to content

Privacy policy

Last updated: August 2026

Tekeats makes ordering software for restaurants. This policy covers three different groups of people, and the answer differs for each: people who visit this website, people who work at a restaurant that uses Tekeats, and diners who order through a restaurant’s Tekeats storefront or app.

Who is responsible for your data, and why it matters

Data protection law distinguishes the party who decides what happens to personal data (the “controller”) from the party who acts on that party’s instructions (the “processor”). Which one Tekeats is depends on whose data it is.

For diner data (orders, accounts, addresses, order history), the restaurant is the controller and Tekeats is the processor. The restaurant decided to collect it and decides what to do with it; we hold and process it on their behalf under a written data processing agreement. If you are a diner and you want your data deleted or corrected, you can ask us and we will act on the restaurant’s instruction, but the restaurant is the party accountable for the decision.

For everything else (enquiries made through this website, the accounts restaurant staff use to sign in, our own billing and support records), Tekeats is the controller and this policy is our own commitment to you.

Our contact for privacy matters is hello@tekeats.com. Write to us there about anything in this policy, including requests about your own data, and a person will read it.

If you visit this website

If you ask for a demo, we store the name, business name, email address, phone number and any message you give us, together with the time of the request. We use it to contact you about Tekeats and to keep a record of the enquiry. The lawful basis is our legitimate interest in responding to a business enquiry you initiated.

Our servers keep technical logs (IP address, the page requested, the time, and the browser’s user-agent string), which we use to operate the site, investigate faults and detect abuse. The lawful basis is our legitimate interest in running a secure and working service.

This website uses Google Analytics to count visits and see which pages are read, but only if you accept the cookie notice. Decline it and no analytics cookies are set. We do not run advertising pixels and we do not track you across other websites. See the cookie policy for the full list of what is set and when.

If you work at a restaurant that uses Tekeats

We hold the account details your employer gave us or that you entered: your name, email address, role, the locations you have access to, and a securely hashed password. We hold records of your activity in the dashboard where that is needed for security and for audit.

We use it to give you access, to secure the account, to provide support, and to communicate with you about the service. The lawful bases are performance of our contract with your employer and our legitimate interest in keeping the platform secure.

Our staff can access a restaurant’s dashboard where it is necessary to investigate a problem. Every such access is logged against the individual who performed it, including when it started and ended. We do this because a support system nobody can audit is a system nobody should trust.

If you order from a restaurant using Tekeats

The platform stores your name, email address and phone number; your delivery address, including its coordinates when you pick it from the address search; the contents, totals and status history of your orders; and any note or allergy information you add to an order.

If you create an account, it also stores your saved addresses, your favourite items, your notification history and, if you upload one, a profile picture.

If you order as a guest, no account is created. A single-use token is generated so you can come back and view that one order; it is stored only as a cryptographic hash, so it cannot be read back out of our database.

If you use a restaurant’s app and allow notifications, a device token is stored so that order updates can reach your phone. You can stop this by turning off notifications for the app or uninstalling it.

Each restaurant’s data is held in its own separate database. One restaurant cannot see another restaurant’s customers or orders. If you order from two different restaurants that both use Tekeats, those are two separate records and they are not joined up.

Payment details: what we never see

Card details are entered into a form served by the payment provider the restaurant uses (Stripe, Revolut or Worldpay) and go directly to them. They do not pass through Tekeats and we do not store them. We never hold a card number, expiry date or security code.

What we do store is the outcome: which payment method was used, the amount, whether it succeeded, the provider’s reference for it, and any refund against it. We need that to show the restaurant and the diner an accurate record of the order.

The payment provider is a controller in its own right for the payment it processes, and its own privacy notice applies to that.

Who else is involved

We use a small number of service providers to run the platform. Each one only receives what it needs for its function.

Hosting and file storage: our servers and object storage, located in the United Kingdom and the EU region of our storage provider (eu-west-2, London). This holds the application and uploaded files such as menu photographs and logos.

Address search and mapping (Google): when you type an address into the address search, what you type is sent to Google’s Places and Geocoding services to return suggestions and coordinates. When a restaurant saves a written address, that address is sent to the same service to obtain coordinates.

Push notifications (Google Firebase Cloud Messaging): device tokens and the content of order notifications, so an update can reach a phone.

Website analytics (Google Analytics): if you accept the cookie notice on this website, Google receives the pages you view and technical details of your visit. This runs on our own marketing website only, never on a restaurant’s storefront.

Payment providers (Stripe, Revolut, Worldpay): whichever the restaurant has connected, for card payments and refunds.

Email delivery: none at present. The platform does not currently send email through an outside provider. When one is engaged, we will add it to this list before any personal data reaches it.

Live order updates are handled by our own server, not a third-party messaging service.

We will keep this list current. Restaurants using the platform are notified of changes to it under the data processing agreement.

Data leaving the UK

The platform and its stored data sit in the UK and the London region of our storage provider. Some of the providers above (Google in particular) process data outside the UK, including in the United States.

Where that happens we rely on the transfer mechanisms those providers make available, which for the UK means the International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, together with the additional safeguards those providers publish.

How long we keep things

Order and payment records: kept for the current financial year plus six years, because UK tax and VAT record-keeping obligations generally require it. This applies even after an account is closed.

Customer accounts: kept while the account is in use. Where an account has had no activity for 36 months we delete or anonymise it, unless the restaurant instructs otherwise as controller.

Demo and contact enquiries: 24 months from our last contact with you.

Guest order tokens: These expire shortly after the order completes, because the token exists only to let a guest track that one order.

Device tokens for notifications: until the app is uninstalled, the token is replaced, or the provider reports it as invalid.

Technical logs: 90 days, extended only where an incident is being investigated.

Backups expire on their own cycle, so deleted data may persist in a backup for a short period after deletion.

Your rights

You have the right to ask for a copy of your personal data, to have inaccurate data corrected, to have data deleted, to restrict or object to processing, and to receive data in a portable form. Where processing relies on consent, you can withdraw it at any time.

If your data is held because you ordered from a restaurant, the restaurant is the controller. Ask them, or ask us and we will pass the request to them and act on their instruction. We will not refuse to help you find the right party.

We will respond within one month. We may ask you to confirm your identity first, so that we are not disclosing someone else’s data to whoever asks.

If you are not satisfied you can complain to the Information Commissioner’s Office at ico.org.uk, or to the supervisory authority where you live. We would rather you came to us first so we can put it right.

How we protect it

Each restaurant’s data lives in its own database rather than in shared tables separated by a filter, so isolation does not depend on every query being written correctly.

Traffic is encrypted in transit. Passwords are stored hashed, never in a readable form. Guest order tokens are stored hashed. Payment credentials that must be held for a restaurant are held server-side and never sent to a browser; only the public identifiers a payment form needs are exposed to the client.

Access for our own staff is limited to those who need it, and access into a restaurant’s dashboard is recorded against the individual.

No system is perfectly secure. If a breach affects your personal data and the law requires us to tell you, we will, and we will tell the restaurant and the ICO where those duties apply.

If you believe you have found a security problem in the platform, tell us at hello@tekeats.com and we will look at it promptly. Please do not test it against live restaurant data.

Children

The platform is not aimed at children and we do not knowingly collect data from children. Ordering food generally requires the ability to enter a contract and to pay. If you believe a child’s data has been collected, tell us and we will remove it.

Changes to this policy

We will update this policy when what we do changes. The date at the top shows the last revision. Where a change materially affects how we handle your data, we will do more than change the date: we will tell the people affected.

Questions about this document? Contact us.